McAfee EPOCDE-AA-BA Product Guide - Page 164

Policy categories, Where policies are displayed, How policy enforcement is set

Page 164 highlights

15 Using policies to manage products and systems Policy management Policy categories Policy settings for most products are grouped by category. Each policy category refers to a specific subset of policy settings. Policies are created by category. In the Policy Catalog page, policies are displayed by product and category. When you open an existing policy or create a new policy, the policy settings are organized across tabs. Where policies are displayed To see all of the policies that have been created per policy category, click Menu | Policy | Policy Catalog, then select a Product and Category from the drop-down lists. On the Policy Catalog page, users can see only policies of the products to which they have permissions. To see which policies, per product, are applied to a specific group of the System Tree, click Menu | Systems | System Tree | Assigned Policies page, select a group, then select a Product from the drop-down list. A McAfee Default policy exists for each category. You cannot delete, edit, export, or rename these policies, but you can copy them and edit the copy. How policy enforcement is set For each managed product or component, choose whether the agent enforces all or none of its policy selections for that product or component. From the Assigned Policies page, choose whether to enforce policies for products or components on the selected group. In the Policy Catalog page, you can view policy assignments, where they are applied, and if they are enforced. You can also lock policy enforcement to prevent changes to enforcement below the locked node. If policy enforcement is turned off, systems in the specified group do not receive updated sitelists during an agent-server communication. As a result, managed systems in the group might not function as expected. For example, you might configure managed systems to communicate with Agent Handler A, but with policy enforcement turned off, the managed systems won't receive the new sitelist with this information, so they report to a different Agent Handler listed in an expired sitelist. When policies are enforced When you reconfigure policy settings, the new settings are delivered to, and enforced on, the managed systems at the next agent-server communication. The frequency of this communication is determined by the Agent-to-server-communication interval (ASCI) settings on the General tab of the McAfee Agent policy pages, or the McAfee Agent Wakeup client task schedule (depending on how you implement agent-server communication). This interval is set to occur once every 60 minutes by default. Once the policy settings are in effect on the managed system, the agent continues to enforce policy settings locally at a regular interval. This enforcement interval is determined by the Policy enforcement interval setting on the General tab of the McAfee Agent policy pages. This interval is set to occur every five minutes by default. Policy settings for McAfee products are enforced immediately at the policy enforcement interval, and at each agent-server communication if policy settings have changed. 164 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Policy categories
Policy settings for most products are grouped by
category
. Each policy category refers to a specific
subset of policy settings. Policies are created by category. In the
Policy Catalog
page, policies are
displayed by product and category. When you open an existing policy or create a new policy, the policy
settings are organized across tabs.
Where policies are displayed
To see all of the policies that have been created per policy category, click
Menu
|
Policy
|
Policy Catalog
,
then select a
Product
and
Category
from the drop-down lists. On the Policy Catalog page, users can see
only policies of the products to which they have permissions.
To see which policies, per product, are applied to a specific group of the System Tree, click
Menu
|
Systems
|
System Tree
|
Assigned Policies
page, select a group, then select a
Product
from the drop-down list.
A McAfee Default policy exists for each category. You cannot delete, edit,
export, or rename these policies, but you can copy them and edit the copy.
How policy enforcement is set
For each managed product or component, choose whether the agent enforces all or none of its policy
selections for that product or component.
From the Assigned Policies page, choose whether to enforce policies for products or components on
the selected group.
In the Policy Catalog page, you can view policy assignments, where they are applied, and if they are
enforced. You can also lock policy enforcement to prevent changes to enforcement below the locked
node.
If policy enforcement is turned off, systems in the specified group do not
receive updated sitelists during an agent-server communication. As a
result, managed systems in the group might not function as expected.
For example, you might configure managed systems to communicate
with Agent Handler A, but with policy enforcement turned off, the
managed systems won't receive the new sitelist with this information, so
they report to a different Agent Handler listed in an expired sitelist.
When policies are enforced
When you reconfigure policy settings, the new settings are delivered to, and enforced on, the
managed systems at the next agent-server communication. The frequency of this communication is
determined by the
Agent-to-server-communication interval
(ASCI) settings on the
General
tab of the
McAfee Agent
policy pages, or the McAfee Agent Wakeup client task schedule (depending on how you implement
agent-server communication). This interval is set to occur once every 60 minutes by default.
Once the policy settings are in effect on the managed system, the agent continues to enforce policy
settings locally at a regular interval. This enforcement interval is determined by the
Policy enforcement
interval
setting on the
General
tab of the
McAfee Agent
policy pages. This interval is set to occur every five
minutes by default.
Policy settings for McAfee products are enforced immediately at the policy enforcement interval, and
at each agent-server communication if policy settings have changed.
15
Using policies to manage products and systems
Policy management
164
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide